Privacy Policy

Iconiqdesign (trading as NOZAIA, Chamber of Commerce (KvK) number 77966473, VAT number NL003265032B62) is responsible for the processing of personal data as described in this privacy policy. If you have any questions, please contact us at info@nozaia.nl.

Who this policy applies to

NOZAIA is a booking platform for salons. This policy applies both to salon owners and their team (the customers of NOZAIA) and to end clients who book an appointment with a salon through a NOZAIA booking page.

What data we process

From salon owners and staff:

From end clients who book an appointment:

From visitors to this website:

What we use this data for

Legal basis

We process personal data on the basis of the performance of a contract (providing the platform or, as the case may be, handling a booking), a legal obligation (for example the statutory tax retention obligation), or our legitimate interest (such as platform security and improvement).

Salons and NOZAIA: who is responsible

For the data of end clients, the salon is the controller and NOZAIA is the processor. The salon and NOZAIA have a data processing agreement. For the data of salon owners and their team, and of visitors to this website, NOZAIA is the controller.

Who we share data with

We engage sub-processors who act solely on our instructions: Supabase (database, stored in Frankfurt), Vercel (hosting, Frankfurt), Resend (email, sent from Ireland), Anthropic (AI features, United States, only when someone uses them) and Stripe (subscriptions). The full list, with what each one does and where, is on the sub-processors page.

For payments by end clients, the salon uses its own account with a payment service (such as Stripe, Sentoo, PayTabs, Paystack or Mopé). That service processes the payment under its own terms.

A salon owner is given access via the dashboard to the data of their own end clients (name, contact details, appointment history) in order to be able to provide their services. Salons are never given access to the data of other salons or their clients.

We do not sell personal data to third parties.

International transfers

We store data in the European Union. Some sub-processors are based in the United States. Where data goes outside the EU, we use the safeguards of the GDPR: the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. Salons outside the EU remain responsible for the rules of their own country on sending data to the EU.

Retention period

We do not retain data for longer than necessary for the purposes set out above, or for as long as the law requires (for example the statutory tax retention period of 7 years for invoice data). If a salon cancels its account, we delete the associated data within a reasonable period, with the exception of data we are legally required to retain.

Your rights

You have the right to:

To exercise these rights, please contact us at info@nozaia.nl. If you are an end client of a salon and would like data about your appointments to be amended or erased, please contact the salon itself in the first instance, because the salon is the controller for that data. In your client account with a salon you can also download your data and delete your account yourself.

Cookies

For information on our use of cookies, please see our cookie policy.

Security

We take appropriate technical and organisational measures to protect personal data against loss or unlawful processing, including encrypted connections and role-based access restrictions.

Changes

We may amend this privacy policy. The date at the top of this page indicates when the most recent change was made.

Privacy Policy | NOZAIA